Executive brief
LORIS is a web-based platform used by researchers to manage neuroimaging data and project information. A security flaw in how the application handles requests for website files (like styles and scripts) allows an attacker to access and download sensitive files from the server that should be private. This could lead to the exposure of confidential research data or system configuration files.
Technical details
A path traversal vulnerability exists in the ModuleFileRouter.php component of LORIS. The application fails to properly validate user-supplied paths in the static file router, allowing an attacker to use traversal sequences to escape the intended directory. By sending specially crafted requests to the /static, /css, or /js endpoints, a remote, unauthenticated attacker can read sensitive files on the underlying file system. The vulnerability is rooted in the lack of path normalization (e.g., using realpath()) before serving files. Patches in versions 27.0.3 and 28.0.1 address this by verifying that the resolved file path remains within the designated base directory.
Affected products
- aces LORIS >= 20.0.0, < 27.0.3; 28.0.0
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched